The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/r354d7654efa1050539fe56a3257696d1faeea4f3f9b633c29ec89609%40%3Cdev.netbeans.apache.org%3E | Mailing List Mitigation Vendor Advisory |
https://www.oracle.com/security-alerts/cpujul2020.html | Patch Third Party Advisory |
Information
Published : 2020-03-30 12:15
Updated : 2023-01-27 10:31
NVD link : CVE-2019-17560
Mitre link : CVE-2019-17560
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
apache
- netbeans
oracle
- graalvm